3 ms·
WTF is that?
by klagan 16y ago
WTF is that?
- willscott 16y agoPresumably on the google website the script is loaded via an xmlhttp request which then strips the initial text and evals the rest. By added the initial throw 1; they prevent other sites from including the script, since it won't do anything.
- klagan 16y agothanks!
- stanleydrew 16y agoIndeed. See this: http://google-gruyere.appspot.com/part3#3__cross_site_script_inclusion http://google-gruyere.appspot.com/part3#3__cross_site_script...
- SimonPStevens 16y agoCool site. I've never seen that before. Learn about web security by breaking it.
- verroq 16y agoWhat about hackthissite.org?
- adrianb 16y agoIf another site would really want to include the script, it could also strip the initial text. Is the purpose only to avoid people from including the script by mistake?
- eddieplan9 16y agoThat's extremely smart. XMLHttpRequest protects you via the same origin policy. But there are other ways (such as JSONP) to load JavaScript and bypass the same origin policy. It's not like you cannot opt out of things like JSONP, but this trick adds another layer of protection and is particularly useful in fighting XSSI.
- nose 16y agoSee line 122 to see how it is used http://svn.apache.org/viewvc/shindig/trunk/features/src/main/javascript/features/core.io/io.js?revision=997164&view=markup#122 http://svn.apache.org/viewvc/shindig/trunk/features/src/main...
- DanielRibeiro 16y agoIt a XHR response that google search yields on the main page. Just use firebug/google chrome's resource tab to see it.